Friday afternoon, half past four: the risk register has to go to the steering committee on Monday morning, and the project manager wonders whether to run the plan through an AI model one more time before sending it off. Two stories circulate around that question, and neither helps. The first story promises that AI will take over risk management: from now on, a model predicts which projects will fail, and the project manager only has to read the dashboard. The second story claims that AI understands nothing of the reality of projects and is therefore a toy at best.
The truth sits squarely in between. Anyone who takes their work seriously cannot afford either caricature. This piece tries to be honest about what AI can and cannot do in project risk management today.
What AI does well
Recognising patterns you no longer see
A language model has, in effect, "read" thousands of project plans, evaluations and post-mortems. As a result, it recognises patterns that an individual project manager encounters at most a few times in a career: the schedule without buffers held together by dependencies, the business case missing structural maintenance costs, the stakeholder section in which the works council does not appear while a reorganisation is hidden in the plan.
This is not magic, and not proof that the AI analysis is equivalent to the judgment of an experienced colleague β no measured reference for that exists. It resembles what a highly experienced colleague does when reading through your plan and saying: "I've seen this before, and it didn't end well" β mainly in that, unlike that colleague, it has no calendar problems.
Enforcing completeness
People identify risks associatively: whatever comes to mind first goes into the table. As a result, risk registers reflect the blind spots of their makers. An AI that systematically walks through a fixed framework (scope, planning, budget, quality, stakeholders) does not skip a category because it feels less interesting or politically awkward.
Precisely those awkward categories are worth their weight in gold. An AI has no difficulty whatsoever noting that the support of a key department is nowhere substantiated. A team member making the same observation thinks twice before writing it down.
Being the tireless second reader
Everyone knows that a fresh pair of eyes on a project plan is valuable. Everyone also knows how rarely it is available. The colleague you ask for a review skims, because they have a project of their own. The PMO quality check arrives once the plan has already been submitted.
AI fundamentally changes the economics of the second reader. A review no longer costs days but minutes, and is therefore also available for interim versions, precisely the moments when feedback is still cheap to process. Moreover, AI reads version seven with the same attention as version one, whereas a human reviewer has long since started scanning only the changes instead of the whole.
What AI cannot do
Knowing the context that is not in the document
An AI assesses what is on paper. But the most important risks of a project are rarely on paper. That the sponsor and the programme director cannot stand each other. That the same supplier underperformed badly on the previous project. That the "available" architect has in reality already been claimed by another programme. Whoever reads the document does not see it; whoever knows the organisation does.
That does not mean the AI analysis is worthless here: a good analysis asks precisely the questions that activate this contextual knowledge. But the answer has to come from you.
Weighing politics
Risk management is to a large extent political work. Which risks do you name explicitly in the steering committee report, and which do you prefer to discuss bilaterally first? How sharply do you word a risk when its cause is sitting at the table? When do you escalate, and when do you give a line manager another week to solve it themselves?
These are judgements in which timing, relationships and instinct come together. An AI can help you formulate the risk sharply; whether and how you put it on the table is craftsmanship that cannot be automated, and that you should not want to automate either.
Bearing responsibility
This is the fundamental boundary. A risk analysis is not an end in itself; it is the underpinning of decisions (continue or stop, adjust or accept, escalate or wait). Those decisions have an owner, and that owner is a human being. "The AI didn't flag the risk" is no defence, any more than "the spell checker didn't catch the mistake" is for an embarrassing letter.
Anyone who adopts AI output uncritically has not automated risk management but abolished it. The judgement (this risk we accept, this one we do not) remains with the project manager. That is exactly why using AI in risk management is also a quality demand on yourself: you must be able to weigh, challenge and supplement the analysis.
AI as a sparring partner: what it looks like in practice
The productive role of AI in risk management is that of sparring partner. Not the decision-maker, not the oracle, but the conversation partner who reads sharply and asks difficult questions. Concretely:
- Before the first version: have AI review your draft plan for gaps and weak substantiation, before you show it to people. That way you spend human review time on the questions that really matter.
- As a devil's advocate: ask explicitly for pushback. "What is the weakest point of this schedule?" yields more than "summarise the risks".
- As a completeness check: put your own risk register next to a systematic AI analysis. The overlap confirms; the differences are interesting. Every risk the AI does see and you do not deserves a conscious decision: rightly ignored, or blind spot?
- Never as the final stop: the AI analysis is input for your judgement, not its replacement. Whatever you adopt, you adopt because after weighing it you agree with it yourself.
The honest conclusion
AI does not make risk management redundant: it raises the bar. The mechanical side of the craft (being complete, recognising patterns, testing consistently) becomes cheap and always available. What remains is precisely the part for which you need a good project manager: context, political sensitivity and the willingness to take responsibility for a decision under uncertainty.
Those who ignore AI leave a tireless second reader unused. Those who trust it blindly confuse a tool with a judgement. In between lies the workable middle ground: let the machine do what the machine is good at, so you can focus your attention on what only you can do.
Want to know what such a review would reveal about your own project plan? RisicoRadar analyses it across five risk categories and fifteen subcriteria, and leaves the judgement where it belongs: with you.